> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction to the Enterprise App Gateway

> This article describes what the enterprise app gateway is, the pain points of accessing intranet apps, solutions for accessing intranet apps, and how to enable and configure the enterprise app gateway.

## What Is the Enterprise App Gateway

The enterprise app gateway lets organizations securely access intranet apps over the Internet. It replaces traditional VPN solutions and improves app access speed based on the network acceleration capabilities of Alibaba Cloud. Built on the zero-trust principle, it provides continuous and dynamic access validation to maximize the security of an organization's digital information.

## Pain Points of Accessing Intranet Apps

Organizations usually place core app systems in the intranet or DMZ and establish network boundary isolation with a firewall. When employees access intranet apps from the Internet through mobile or PC devices, they use one of two methods: VPN dial-up and port mapping. However, VPN devices may have vulnerabilities, or ports may be mapped to external IP addresses or URLs. As a result, hackers can directly access or attack apps, leading to leaks of an organization's core data.

The following describes the four main pain points that users face when accessing intranet apps with legacy methods.

| Pain Point                | Description                                                                                                                                                                                              |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| High financial cost       | Traditional VPN solutions are costly to deploy, and dedicated lines incur substantial fees every year.                                                                                                   |
| Poor user experience      | - Employees must install and configure the VPN client in advance, which is cumbersome. - They must first dial up the VPN before use, and the VPN disconnects on weak networks and requires reconnection. |
| Data insecurity           | The inbound firewall ports must be kept open, which lets hackers scan the ports of intranet apps and launch attacks.                                                                                     |
| Difficult device delivery | The process from raising a purchase request to receiving, installing, and configuring a device usually takes several months and involves complex debugging.                                              |

## Solutions for Accessing Intranet Apps

### Recommended Solution

The DingTalk enterprise app gateway securely connects an organization's intranet apps to the Alibaba public cloud environment through the DingTalk identity platform, the DingTalk security gateway, and the Connector. This lets employees conveniently access internal apps in office, operations and maintenance, and branch scenarios, supporting the digital and collaborative transformation of organizations.

The following describes the five recommended solutions for users to access intranet apps.

| Solution                               | Description                                                                                                                                                                                                                                                                                                                                                                                                             |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Set access policies for specific apps  | Set access policies for specific apps by organization, department, role, or individual.                                                                                                                                                                                                                                                                                                                                 |
| Simple configuration and fast delivery | Deploy only the Connector within your organization (which establishes a reverse persistent connection to the DingTalk server). A one-line installation script is provided. After installation, the admin completes delivery with simple configuration in the gateway console.                                                                                                                                           |
| Full-link encryption                   | Quickly onboard intranet apps to DingTalk. After you install and deploy the Connector on your intranet server, a securely encrypted transmission channel is established between the gateway and the intranet. Requests from the employee's DingTalk client are transmitted to the intranet server through this channel, and the server response is returned to the employee's DingTalk client through the same channel. |
| Block illegal identities               | Based on DingTalk identity authentication, the gateway's authentication protects intranet resources and blocks malicious access from external parties. Only requests that pass DingTalk identity authentication are forwarded to the organization's server.                                                                                                                                                             |
| Support for rewrite                    | With custom rewrite rules, the gateway supports rewriting the request header, request body, response header, and response body.                                                                                                                                                                                                                                                                                         |

### Product Design Recommendations

| Product          | Product Design Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Client-side      | - The DingTalk client mainly verifies user identity information to ensure the legitimacy of accessing users. - It binds employee identities based on DingTalk accounts to achieve secure identity verification and state maintenance. - It ensures account security through DingTalk's built-in account risk control logic. - It prevents malicious attacks such as credential stuffing, account theft, and brute-force cracking.                                                                                                                                                                     |
| Security gateway | - The core component of the DingTalk zero-trust security solution, this gateway is an identity-aware proxy. - It works at Layer 7 (the application layer) of the OSI model and implements a reverse proxy for the HTTP(S) protocol while verifying the legitimacy of every access request from the client. - Because the HTTP(S) protocol supports short connections and does not require persistent connections, it delivers highly stable remote access, works reliably on weak networks, and never "drops offline." - This gateway is a SaaS service deployed as clusters across multiple regions. |
| Connector        | - The Connector is deployed in the DMZ of the customer's equipment room. - It establishes a reverse connection to the DingTalk enterprise app security gateway through the firewall, forwards client requests to internal apps, receives the returned content from internal apps, and sends it back to the client through the DingTalk enterprise app security gateway. - With this component, the intranet is hidden, and internal apps do not need to be exposed to the Internet through the firewall, greatly reducing attacks.                                                                    |

## App Gateway Integration Case

A financial IT enterprise previously accessed its internal office system through a traditional VPN. Employees had to dial up the VPN before entering the intranet system, and the complex configuration meant that many employees did not know how to use it and had to reconfigure it after changing phones. In addition, because the VPN relied on persistent connections, it frequently disconnected on weak networks such as on high-speed trains and in elevators, requiring repeated dial-ups and resulting in low collaboration efficiency.

After adopting the DingTalk enterprise app gateway, the enterprise no longer opens firewall ports, so viruses and hackers cannot get in. Employees can quickly, conveniently, and securely access internal systems anytime and anywhere for efficient collaboration.

## How to Enable the Enterprise App Gateway

To enable it for a DingTalk organization, use the DingTalk mobile app to scan the QR code below and install the **DingTalk Enterprise App Gateway** app.

## How to Configure the Enterprise App Gateway

To configure the enterprise app gateway, see Enterprise App Gateway Configuration Process.

**Step 1: Configure the Connector**.

**Step 2: Configure App Management**.

**Step 3: Configure access policies**.

## Service Support

Quickly onboard intranet apps to DingTalk. After you install and deploy the Connector on your intranet server, a securely encrypted transmission channel is established between the gateway and the intranet. Requests from the employee's DingTalk client are transmitted to the intranet server through this channel, and the server response is returned to the employee's DingTalk client through the same channel.

If you need a consultation, visit this [link](https://partner.dingtalk.com/opportunity_web.html?channel=open\&templateId=8e5ea46355fe4b7eac24f3488b845d20#/consultingService) or scan the QR code below. Fill in the basic information to complete and submit your appointment request, and we will contact you.
